First published: Fri Apr 13 2018(Updated: )
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ikiwiki | 3.20190228-1 3.20200202.3-1 | |
Ikiwiki Hosting Project | <3.20170111 | |
Debian | =7.0 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0356 is classified as a vulnerability that allows for authentication bypass, posing a significant security risk.
To fix CVE-2017-0356, upgrade to version 3.20190228-1 or 3.20200202.3-1 of the ikiwiki package.
CVE-2017-0356 affects ikiwiki versions prior to 3.20170111.
Any attacker with the ability to send requests to the ikiwiki application can exploit CVE-2017-0356 through crafted parameters.
Exploiting CVE-2017-0356 allows attackers to bypass authentication, potentially leading to unauthorized access and data compromise.